Malicious PDF — malware analysis report

Static analysis result for SHA-256 54d1477ac54383f0…

MALICIOUS

PDF

58.7 KB Created: 2006-02-16 15:03:51 -08:00 Authoring application: lice (via ubst)
MD5: 35200e50c208315539d434c207ea0be7 SHA-1: bdeda8808f148eaf7ab05caa7a6a01edf5e64bf1 SHA-256: 54d1477ac54383f09a5c3a60155b57f9309b97ad25f40ddef9b438e7c18faa1b
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The PDF was flagged by ClamAV as 'Pdf.Exploit.Dropped-94' and a machine learning classifier assigned a high probability of maliciousness. Embedded JavaScript was detected, indicating the likely intent to download and execute a secondary payload. The document body contains obfuscated metadata and does not provide user-facing content to analyze.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Exploit.Dropped-94 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-94
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0076_000.js
d4c1287bac93dd16d95edc0ab676e90fd5f23ccd4d7a0ab2410167537081703d
pdf-javascript-stream PDF /JS object 76 at offset 0x955 50144 bytes